CVE-2025-36539: AVEVA PI Data Archive Uncaught Exception
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36539?
CVE-2025-36539 has a high severity rating since it allows authenticated users to trigger a denial of service by shutting down critical subsystems.
How do I fix CVE-2025-36539?
To fix CVE-2025-36539, you should upgrade to the latest version of AVEVA PI Data Archive or PI Server that is patched against this vulnerability.
Who is affected by CVE-2025-36539?
CVE-2025-36539 affects users of AVEVA PI Data Archive versions up to 2018 SP3 Patch 4 and all versions of AVEVA PI Server prior to the latest patches.
What is the impact of exploiting CVE-2025-36539?
Exploiting CVE-2025-36539 can result in a denial of service, impacting the availability of essential PI Data Archive subsystems.
Are there any workarounds for CVE-2025-36539?
Currently, no specific workarounds are recommended for CVE-2025-36539 besides applying the necessary updates as soon as possible.